The EU AI Act at a Glance

Operating AI Systems Safely, Transparently, and in Compliance with Regulations
Microchip processor on a glowing circuit board featuring the EU flag and "EU AI Act" lettering.

July 30, 2026, Reading time: 8 minutes

At a Glance: The EU AI Act with STACKIT

  • What is the EU AI Act? A Europe-wide legal framework that sets binding rules for the use of artificial intelligence based on four risk classes (unacceptable, high, limited, minimal).
  • Who does it affect? All companies, government agencies, and providers (providers & deployers) that develop, distribute, or use AI systems in the EU.
  • STACKIT’s Solution: A sovereign, European cloud platform with certified security standards (ISO 27001, C5) and AI Model Serving for the legally and data-protection-compliant use of AI.
  • Benefits for organizations: Full data sovereignty, structured compliance with documentation and audit requirements, and no need to retrain models using their own user data.

Regulated AI in Europe: How STACKIT Guides Companies Safely Through the AI Act

Hardly any other technology has transformed the world of work as rapidly as artificial intelligence (AI). It analyzes data, supports medical diagnoses, and automates processes—in the process, it is transforming entire industries. But with progress comes greater responsibility, as the consequences of unregulated AI use are incalculable.

That is why the European Commission has taken action and created a globally unique legal framework with the AI (Artificial Intelligence) Act. The regulation has been in effect since May 21, 2024, and will be phased in by mid-2026. Starting in 2025, new, binding requirements have been introduced for all companies that develop, deploy, or distribute AI systems in the member states of the European Union.

For many users and providers, now—at the very latest—is the time to review their AI projects for compliance and implement them in a structured manner. Find out here what the AI Regulation covers in detail, what specific tasks you’ll face, and how your company can adapt to these requirements.

Key Terms Related to the AI Act with STACKIT

The AI Act with STACKIT: Your Benefits at a Glance

The implementation of the AI Regulation, adopted in 2024 by a European body of member states, poses major challenges for many market participants. Transparency, security, clear processes, and a reliable infrastructure that complies with the legal framework are required. STACKIT’s cloud solution is specifically tailored to the application of the EU regulation and offers you many benefits:

EU-compliant cloud infrastructure

STACKIT’s high-performance cloud infrastructure meets all key requirements of the AI Act, such as data protection, risk management, governance, and technical compliance. This provides legal certainty and strengthens trust in artificial intelligence.

Regulatory Compliance Made Easy

STACKIT supports organizations in fulfilling their legal obligations. This includes risk analyses, technical documentation, and compliance with transparency requirements for high-risk systems. This enables the provisions of the AI Act to be implemented in a structured and efficient manner.

Verified security and certified standards

STACKIT’s certifications, such as ISO 27001 and C5, comply with the security requirements set forth in the AI Act. This is particularly important for high-risk applications in the healthcare, industrial, and public administration sectors.

Transparency and Traceability of AI Applications

The platform enables the complete documentation of all AI processes. This makes it possible to trace models, data processing, and dependencies on other systems at any time. Requirements for auditability and the obligation to provide evidence to regulatory authorities are reliably met.

Secure Use of Generative AI Models

STACKIT AI Model Serving supports the privacy-compliant use of GPAI and GenAI models, such as Llama 3.1. No user data is stored or used for training. This makes it easier to comply with the new requirements for transparency and data protection.

Future-proof thanks to continuous development

STACKIT is continuously developing its platform to accommodate future EU regulations, such as the Data Act, as well as industry-specific regulations. This ensures that you remain compliant in the long term.

The AI Regulation in Detail: Obligations, Risk Categories, and Responsibilities for Your Company

The AI Act is a law that comprehensively regulates the use of artificial intelligence in the European Union. The goal of the regulation is to design AI systems in a way that is compatible with European values—such as the protection of fundamental rights, data protection, and transparency. The higher the risk to individuals and society, the stricter the requirements.

Four Risk Categories of AI Systems According to EU Law

  • Unacceptable risk: AI systems that violate fundamental rights, deliberately manipulate people, or disparage them areprohibited . Also prohibited are systems that evaluate groups of people based on their social behavior, such as when granting loans or providing access to social benefits. The use of biometric systems—such as facial recognition in public spaces—is subject to particularly strict regulations. Article 5.1 of the AI Act defines these and other practices as unacceptable risks and prohibits their use throughout the European Union.
  • High Risk: Article 6 of the Regulation classifies systems with serious implications for safety or fundamental rights—such as those in medicine, the judiciary, or critical infrastructure—as high-risk. Organizations are required to provide comprehensive documentation, conduct risk analyses, and perform human evaluations.
  • Limited risk: This category includes chatbots and recommendation systems. They must be labeled as AI and must not mislead users.
  • Minimal risk: This category includes spam filters and automatic translations. These are considered low-risk and are not subject to any special requirements.

What regulations must companies comply with?

All affected providers and users are required to systematically record the AI systems they use. These must be classified and assessed according to the criteria of the AI Act. Based on this, appropriate measures must be taken to ensure compliance with legal requirements. For high-risk AI systems, additional requirements apply, such as comprehensive documentation, regular inspections and audits, and transparent information provided to end users. Furthermore, organizations must in the future provide evidence that their AI systems comply with the law at all times.

The AI Act in Practice with STACKIT

The regulation applies to anyone who develops, distributes, or uses artificial intelligence within the European Union—regardless of whether they are a startup, a small or medium-sized enterprise, or an international corporation. The sole determining factor is whether an AI system is used in the European market. The focus is on sectors that handle sensitive data and have a high impact, such as public administration, industry, healthcare, the financial sector, and retail. Even if you import or further process AI models from third countries, you are subject to these requirements. This ensures uniform rules apply to all market participants in the EU member states.

Hands typing on a laptop with a glowing holographic file folder system, representing digital administration, a paperless office, and secure document management.

Efficient Application Processing with Transparent AI

Local governments often use AI-powered systems for automated application processing in their citizen services—such as for housing allowance applications or certificates of residence. With the certified STACKIT Cloud, all data remains in Europe. The platform can also support municipalities in conducting structured risk analyses and fulfilling transparency and audit requirements. This allows administrative processes to be streamlined without violating regulatory requirements.

Go to the Public Sector page
Doctor in a lab coat using a tablet with futuristic blue medical holograms like ECG, health data, and AI symbols, representing digital health and modern healthcare technologies.

Diagnostics Using AI That Complies with Regulations

Reliability plays a central role in healthcare—especially when AI is used in diagnostics. STACKIT AI Model Serving enables the processing of sensitive health data exclusively in certified data centers within the EU. At the same time, the platform supports you in ensuring complete documentation, traceability of model decisions, and the integration of human oversight. This allows for the secure integration of innovation and regulation.

Visit the Healthcare Industry Page
High-tech, automated warehouse control panel with a transparent data visualization screen, directing a conveyor belt system within a logistics center.

Ensuring Quality with AI

Manufacturing companies that rely on automated quality assurance face the challenge of integrating AI models in a way that is not only effective but also compliant with regulations. With STACKIT, you can centrally manage data streams and model versions, systematically assess risks, and reliably meet regulatory requirements—even across complex supply chains.

Go to the Manufacturing Industry Page
Hand holding a smartphone displaying a glowing shopping cart icon against a blurred supermarket background, symbolizing the integration of retail and digital e-commerce.

Transparency in Personalized Recommendations

Where customer expectations meet intelligent product recommendations, AI has long been a standard tool. With STACKIT, online retailers can ensure that all customer data is processed in compliance with the AI Act and the GDPR. The platform offers features for transparently labeling AI-based information, simplifies compliance documentation for regulatory authorities, and fosters trust on both sides.

Go to the Retail Industry Page

Practical Tips for Getting Started with the AI Act Using STACKIT

The AI Act has already clearly defined the rules for 2024. So 2025 is the right time to set the course for your approach to AI. This will help you avoid future risks and lead AI projects to success in compliance with the regulations. The following tips will help you take a structured and practical approach.

Get an overview early on

Identify all AI systems in use and assign them to the appropriate risk classes. A centralized AI inventory significantly simplifies management, documentation, and future tracking.

Assess risks systematically

Use established frameworks such as CapAI or the NIST AI Risk Management Framework to analyze regulatory, technical, and ethical risks in a structured manner. This allows you to identify vulnerabilities early and take targeted countermeasures.

Integrate documentation into your process from the very beginning

Document technical parameters, data sources, training data, and compliance evidence for each AI system in a structured manner. This reduces the effort required in the event of an audit and provides greater assurance both internally and externally.

Ensure transparency

Label AI-powered applications and provide information on how they work. For many processes, this is not only required by law but also strengthens trust in your services.

Train your staff

By law, everyone who works with high-risk AI must have the appropriate skills. Offer regular cross-departmental training on governance, ethical guidelines, and legal requirements.

Review your processes regularly

Compliance is not a static state. Establish internal controls, regular audits, and update processes to ensure you can respond promptly to new legal requirements or technical changes.

Eine Hand berührt ein digitales Touch-Display mit leuchtenden EU-Sternen und dem Schriftzug „AI Act“.

Navigating AI Regulations Safely with STACKIT

The AI Act brings not only new obligations but also the opportunity to use artificial intelligence responsibly and in a future-proof manner. For you, this means greater structure and transparency within a clear legal framework. With STACKIT as your European cloud partner, you can efficiently overcome the challenges posed by the AI Act. Whether in government, industry, healthcare, or retail—in 2025, you, too, can rely on AI systems that can maximize your potential both today and in the future.

Frequently Asked Questions About the AI Act with STACKIT

Who is subject to the AI Act?

It applies to all companies that develop, distribute, or use AI systems in the European Union—regardless of industry, size, or place of business.

What counts as a high-risk AI system?

These include applications with potentially serious impacts on health, safety, or fundamental rights—for example, in medicine, the justice system, or critical infrastructure.

What are the penalties for violations?

Fines of up to 6% of global annual revenue or up to 30 million euros may be imposed for noncompliance.

When must the regulations be implemented?

The European Commission adopted the package of measures in May 2024. The first regulations—such as bans on particularly high-risk AI applications—must be implemented by August 2024. Most obligations—especially those for high-risk systems—will take effect starting in mid-2025 and will be fully implemented by August 2026.